« 2025 »

778 reports

2025-07-28
Rekt
#WooX
2025-07-22
Rekt
#CoinDCX
2025-07-28 • Rekt

WOO X suffered a $14 million breach after a targeted phishing attack compromised a team member’s device and exposed access to the development environment. The attacker used that access to reach hot-wallet-related systems and coordinate withdrawals across …

#WooX
2025-07-28 • Wiz

TraderTraitor is presented as a North Korean financially motivated activity cluster focused on stealing cryptocurrency and other digital assets from blockchain and cloud-connected organizations. The excerpt ties the cluster to Lazarus Group, APT38, BlueNo…

#TraderTraitor #JumpCloud #NPM #DMM #Bybit #T1082 #T1041 #T1555 #T1071.001 #T1195.002 #T1059.006 #T1059.007 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1566.001 #T1059 #T1199 #T1105 #T1553.002 #T1552.004 #T1195.001 #T1078 #T1087.004 #T1580 #T1578.005 #T1588.003 #T1550.004 #T1609
2025-07-26 • Bloo

InvisibleFerret is described as a Python-based backdoor used by Lazarus Group or Famous Chollima in Contagious Interview operations against developers, cryptocurrency workers, finance targets, and other technology professionals. The infection chain relies…

#ContagiousInterview #InvisibleFerret #T1082 #T1059.003 #T1567.002 #T1041 #T1071.001 #T1195.002 #T1115 #T1083 #T1056.001 #T1027 #T1204.002 #T1566.003 #T1555.003 #T1219 #T1562.001 #T1571 #T1016 #T1560.001 #T1543.003 #T1578
2025-07-23 • USFBI

The FBI warns that North Korean IT workers continue targeting U.S. businesses to obtain fraudulent employment, access company networks, and generate revenue for the DPRK in violation of U.S. and U.N. sanctions. The activity relies on identity obfuscation …

#ITWorker
2025-07-23 • Ahnlab

ASEC identified RokRAT distribution through malicious Hangul Word Processor documents rather than the malware's more typical LNK-based delivery chain. A North Korea grain-store-themed lure embedded ShellRunas.exe and credui.dll as OLE objects, which the H…

#RokRAT
2025-07-22 • Rekt

Rekt attributes the CoinDCX incident to attackers who allegedly prepared the theft over several days, funding activity with 1 ETH from Tornado Cash before routing through FixedFloat, Polygon, deBridge and Solana. The article describes a July 18 drain of a…

#CoinDCX